Hacker News new | ask | show | jobs
by llm_nerd 926 days ago
RCS uses transport encryption and I honestly have no idea if it uses cert pinning or server certs or the like. The bigger concern to me is that it puts your telco in charge, just like the old days of SMS. Without E2E they get to see all of the contents of messages and to share it with whoever they deem they want to share it with, which history has shown is too many people. Telcos were very willing partners in the development of RCS for a reason. And there's a reason the base spec doesn't include E2E. Telcos want a return to the good old days.

SMS is insecure and no one should use it. RCS isn't that much better and history is a lesson that it returns to a partner that isn't trustworthy.